PT-2026-56542 · Litellm · Litellm

CVE-2026-59819

·

Published

2026-07-08

·

Updated

2026-07-23

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LiteLLM versions prior to 1.83.10-stable
Description LiteLLM is a proxy server that functions as an AI Gateway for calling LLM APIs. The '/health/test connection' endpoint resolves request-supplied environment and OIDC file references within the litellm params parameter. This allows a proxy administrator or a privileged caller with permissions to test model connections to read files from the local filesystem using an oidc/file/ reference.
Recommendations Update to version 1.83.10-stable.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59819
ECHO-AB2A-73D9-3AA2
GHSA-4G5M-C9R5-49XF
PYSEC-2026-3476

Affected Products

Litellm